Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Conquerors Electronic Army

Conquerors Electronic Army

TLP:CLEAR
Active

Also known as: APT28, Fancy Bear, GalaxyGato, Nimbus Manticore, aerospace, telecommunications, tracked as, Tunisian, Earth Bluecrow, DecisiveArchitect, Red Dev 18, the Newscaster Team, Tunisian Maskers Cyber Force, Subtle Snail, focused on defense, government entities, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, Pawn Storm, MiniDionis, Chinastrats, 2026, Altoufan Team, regional government enti, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork, Haywire Kitten

Description

Conquerors Electronic Army operates under the “Wa’d al‑Akhira” banner and claims responsibility for a range of disruptive operations, including mass DDoS blasts against Israeli civil and defense entities, and sabotage of critical infrastructure in the Middle East. Their tactics combine high‑volume traffic floods with credential harvesting via malicious mobile applications, as well as targeted wiper malware designed to incapacitate industrial control systems. The group’s attacks are often coordinated across multiple platforms – from rented stressers for volumetric pressure to exploit kits that deliver malicious APKs for phishing and exfiltration. Reports attribute a 149‑attack wave in early March 2026 to CEA and allied pro‑Russian or pro‑Iranian actors, illustrating an operational tempo capable of influencing national security infrastructure. CEA does not seek only disruption; there are indications of influence operations, as evidenced by defacement (T1491) and the embedding of links to a UK‑registered charity during campaigns. Their multi‑faceted approach demonstrates both opportunistic and ideologically driven motives, targeting sectors that provide strategic leverage over regional politics.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Non profit
Energy
Critical infrastructure
Aerospace
Media
Maritime
Healthcare
Manufacturing
Education
Information technology
Think tank
Pharmaceutical
Retail
Chemical
Mining
Aviation
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
IR
IL
CN
GB
IN
JP
DE
KR
SA
RU
TW
FR
CA
PK
AU
TR
KZ
AE
VN
UA
PL
IQ
BY
SG
NL
BR
ES
IT
SY
MX
RO
LB
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Conquerors Electronic Army (CEA) is a hybrid, pro‑regional threat actor that blends disruptive denial‑of‑service campaigns with sabotage against industrial control systems and credential‑exfiltration efforts. They target government, defense, financial, and critical‑infrastructure sectors across the Middle East, Israel, Russia, Iran, and neighboring nations, using volumetric DDoS attacks to disrupt services while deploying wiper malware and phishing through mobile apps to gain long‑term footholds.

Goals & Targeting

CEA’s strategic objectives blend political advocacy with cyber sabotage aimed at weakening rival state capabilities. By attacking high‑visibility government and defense entities – including SCADA facilities, military communications, and financial institutions – they aim to create instability and showcase technological superiority for their perceived supporters. Their use of social engineering via mobile apps suggests an effort to sow mistrust and acquire credentials that could be leveraged in future influence campaigns. The actor’s focus on the Middle East indicates a clear geopolitical agenda tied to regional power dynamics involving Iran, Russia, and Israel.

Enhanced Description

Key Capabilities

  • Volumetric Distributed Denial‑of‑Service attacks
  • Phishing via malicious mobile applications
  • Credentials harvesting from password stores
  • Wiper malware targeting industrial control systems (SCADA)
  • Hack‑and‑leak operations including defacement
  • Exfiltration over command‑and‑control channels

MITRE ATT&CK Tactics

Impact
Credential Access
Initial Access

ATT&CK Techniques

T1499
T1555
T1486
T1485
T1566.001
T1410
T1218.005
T1041
T1110
T1476

Software / Tooling

Crimson
Anchor
Epic
Shamoon
Shark
Samurai
DEADEYE
Mythic
Matrix
Dark
Nexus
Rogue
Poseidon
Tsunami
Predator
Leverage
Buhtrap
DarkHotel
gcman
Global
Handala
Jackal
Lynx
Naikon
Nitro
Snake
TeamSpy
Void
Hellsing
Telegram
Wiper
Hidden Cobra
UNC1549
MuddyWater

Campaigns & Victims

CEA’s campaigns illustrate a recurring pattern of synchronized, multi‑vector assaults that target both the service layer and control infrastructure. In March 2026 they launched 149 volumetric DDoS attacks across 16 countries, simultaneously distributing phishing through malware‑laden mobile apps and deploying wiper payloads to industrial networks. The actor’s operations are generally rapid yet coordinated, indicating a well‑structured threat group capable of leveraging rented stresser services for large‑scale disruption while maintaining stealthy credential exfiltration channels. Their choice of victims—government agencies, defense contractors, energy utilities, and financial institutions—underscores an intent to cripple critical national assets.

IOC Patterns

  • Domain-based command & control infrastructure
  • Malicious email addresses used in spear‑phishing
  • Traffic spikes indicative of volumetric DDoS attacks
  • Indicators linked to malicious mobile apps
  • Credentials exfiltration file hashes
  • Wiper malware registry or filesystem modifications

Recommended Actions

  • Deploy advanced DDoS defense solutions and monitor traffic for sudden volume spikes; block known stresser servers identified in threat intel feeds.
  • Implement multi‑factor authentication (MFA) on all credentials, especially those stored locally or accessed remotely by SCADA operators; harden access control to critical infrastructure networks.
  • Conduct regular security awareness training focusing on mobile app phishing scenarios; institute a rigorous verification process for new applications.
  • Establish backup and recovery procedures for industrial control systems; run forensic checks for file integrity anomalies indicative of wiper activity.
  • Integrate threat‑intelligence feeds to detect IOC patterns tied to CEA, such as known malicious domains and email addresses; continuously update prevention rules accordingly.

Suggested Tags

hacktivism
DDoS
SCADA sabotage
critical infrastructure attacks
credential harvesting
mobile app phishing
industrial control system sabotage
pro-Russian group
pro-Iranian group
Middle East targeting
government sector attacks

Confidence Assessment

The confidence level is moderate, based on reports from Rescana and Radware that identify Conquerors Electronic Army in coordinated campaigns and attribute specific tactics. However, concrete attribution remains challenging due to reliance on single‑source analyses, evolving alias usage, and lack of publicly detailed technical signatures for all observed attacks. Gaps persist regarding precise timelines, motive clarity beyond disruptive intent, and the full extent of their toolset.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.rescana.com — Cited by web research for: GalaxyGato
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. thehackernews.com — Cited by web research for: 2026
  4. www.recordedfuture.com — Cited by web research for: Void
  5. https://www.radware.com — Cited by AI analysis.
  6. https://www.rescana.com — Cited by AI analysis.
  7. https://attack.mitre.org/techniques/T1499 — Cited by AI analysis.
  8. https://attack.mitre.org/techniques/T1555 — Cited by AI analysis.

Intel Summary

13

Techniques

43

Tools

0

Campaigns

20

IOCs

0

Observed Data

6

Tactics

Tags

Healthcare Targeting
DDoS
Government Targeting
Influence Operation
Disruption
Middle East
Israel
Civil Sector
Healthcare Sector
hacktivism
SCADA sabotage
critical infrastructure attacks
credential harvesting
mobile app phishing
industrial control system sabotage
pro-Russian group
pro-Iranian group
Middle East targeting
government sector attacks

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.